← All speakers

Bio, Work & Ideas

Den Delimarsky

Conference affiliation: Microsoft · 2025

Den Delimarsky is a lead maintainer of Model Context Protocol and a Member of Technical Staff at Anthropic. He shapes the open protocol’s authorization architecture, security, software-development kits, and governance, helping AI applications connect to external tools without overriding the identity and permissions of their users.

After six years at Microsoft, Delimarsky joined Amazon Web Services in 2020 as a Senior Product Manager, Technical, working on Amazon EventBridge and event-driven infrastructure. He subsequently returned to Microsoft before joining Netlify in 2021 as a Group Product Manager focused on developer tools and web experiences.

During a third Microsoft tenure, Delimarsky worked in Microsoft Security before moving into its Developer Division and CoreAI. As a Principal Product Engineer, he worked on authentication, authorization, developer tooling, GitHub Copilot adoption, and emerging MCP security challenges. He also helped launch GitHub Spec Kit with John Lam and contributed to MCP governance and authorization.

He joined Anthropic in January 2026 as a Member of Technical Staff and was appointed an MCP lead maintainer that April. His responsibilities span the protocol specification, SDKs, security, community governance, and developer experience.

  • User identity must survive agent handoffs. Delimarsky helped develop an MCP authorization model that separates resource servers from OAuth authorization servers, allowing established identity providers to issue tokens while MCP servers validate them. Protected-resource metadata directs clients to the correct provider, and OAuth resource indicators bind tokens to their intended resources. His work on protected MCP servers demonstrates how these safeguards preserve different users’ permissions without requiring every server developer to build an authorization system.
  • Agent inputs are part of the attack surface. Delimarsky and Sarah Young coauthored guidance on indirect prompt injection, describing how hostile instructions can enter AI systems through documents, webpages, emails, or manipulated MCP tool descriptions. Their recommendations emphasize trust boundaries, approved dependencies, monitoring, and software-supply-chain security.
  • Coding agents need explicit specifications. GitHub Spec Kit supports spec-driven development by organizing AI-assisted programming around written specifications, technical plans, reviewable tasks, and implementation checkpoints. Delimarsky’s description of the workflow keeps developers responsible for validating each stage.
  • Interactive AI tools require isolation. His writing on MCP Apps describes interactive HTML interfaces built on existing protocol abstractions and isolated inside host-controlled, sandboxed frames. His independent developer projects also include PowerToys Awake, DeckSurf, and BlogScroll.

Read the topics behind these talks

1 conference talk

References